CVE-2013-0209

high
Published 2013-01-23 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.5

Description

lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-24321 remote multiple verified
Metasploit ยท 2013-01-07

Movable Type 4.2x/4.3x - Web Upgrade Remote Code Execution (Metasploit)

Source code queued for fetch โ€” refresh in a moment.

Metasploit modules

Movable Type 4.2x, 4.3x Web Upgrade Remote Code Execution
Source fetch failed: fetch_error โ€” view the original via the link above.

Application impact

VendorProductVersionsFixed
sixapartmovable_type4.21
sixapartmovable_type4.22
sixapartmovable_type4.23
sixapartmovable_type4.24
sixapartmovable_type4.25
sixapartmovable_type4.26
sixapartmovable_type4.27
sixapartmovable_type4.28
sixapartmovable_type4.29
sixapartmovable_type4.31
sixapartmovable_type4.32
sixapartmovable_type4.33
sixapartmovable_type4.34
sixapartmovable_type4.35
sixapartmovable_type4.36
sixapartmovable_type4.37
sixapartmovable_type4.38
sixapartmovable_type4.261
sixapartmovable_type4.291
sixapartmovable_type4.292
sixapartmovable_type4.361

References

CWEs

CWE-287

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.